- Table of Contents
-
- 07-System
- 01-High availability group
- 02-VRRP
- 03-Track
- 04-BFD
- 05-NQA
- 06-Basic log settings
- 07-Session log settings
- 08-NAT log settings
- 09-AFT log settings
- 10-Threat log settings
- 11-Application audit log settings
- 12-NetShare log settings
- 13-URL filtering log settings
- 14-Attack defense log settings
- 15-Bandwidth alarm logs
- 16-Configuration log settings
- 17-Security policy log
- 18-Heartbeat log settings
- 19-IP access logs
- 20-WAF log settings
- 21-Bandwidth management logs
- 22-Context rate limit logging
- 23-Report settings
- 24--Session settings
- 25-MAC authentication online users
- 26-Signature upgrade
- 27-Software upgrade
- 28-License management
- 29-IRF
- 30-IRF advanced settings
- 31-Contexts
- 32-Administrators
- 33-Date and time
- 34-MAC address learning through a Layer 3 device
- 35-SNMP
- 36-Configuration management
- 37-About
- 38-Reboot
- 39-Ping
- 40-Tracert
- 41-Packet capture
- 42-Webpage Diagnosis
- 43-Diagnostic Info
- 44-Packet trace
- 45-Load balancing test
- 46-IPsec diagnosis
- 47-Fast Internet Access
- 48-IP reputation log settings
- 49-Load balancing logging
- Related Documents
-
Title | Size | Download |
---|---|---|
08-NAT log settings | 27.76 KB |
NAT log settings
This help contains the following topics:
¡ NAT resources exhaustion log settings
Introduction
NAT session log settings
NAT session logging records NAT session information, including translation information and access information. NAT session logs can be output in flow logs or fast logs. By default, NAT session logs are output in flow logs.
The device generates NAT session logs for the following events:
· NAT session establishment.
· NAT session removal. This event occurs when you add a configuration with a higher priority, remove a configuration, change ACLs, when a NAT session ages out, or when you manually delete a NAT session.
· Active NAT session logging.
NAT444 log settings
NAT444 logs are used for user tracing. The NAT444 gateway generates a user log whenever it assigns or withdraws a port block. The log includes the private IP address, public IP address, and port block. You can use the public IP address and port numbers to locate the user's private IP address from the user logs. NAT444 logs can be output only in fast logs.
A NAT444 gateway generates NAT444 logs when one of the following events occurs:
· A port block is assigned.
For the NAT444 static port block mapping, the NAT444 gateway generates a user log when it translates the first connection from a private IP address.
For the NAT444 dynamic port block mapping, the NAT444 gateway generates a user log when it assigns or extends a port block for a private IP address.
· A port block is withdrawn.
For the NAT444 static port block mapping, the NAT444 gateway generates a user log when all connections from a private IP address are disconnected.
For the NAT444 dynamic port block mapping, the NAT444 gateway generates a user log when all the following conditions are met:
¡ All connections from a private IP address are disconnected.
¡ The port blocks (including the extended ones) assigned to the private IP address are withdrawn.
¡ The corresponding mapping entry is deleted.
NAT resources exhaustion log settings
After you enable NAT resource exhaustion logging, the device outputs logs when the NAT resources run out. In NO-PAT, the NAT resources refer to the public IP addresses. In EIM PAT, the NAT resources refer to public IP addresses and ports. In NAT444, the NAT resources refer to public IP addresses, port blocks, or ports in port blocks. To enable the device to generate logs for NAT444 resource exhaustion events, enable fast log output in conjunction with this feature.